Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware18 jun 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
CVE-2018-7600 0-Day Exploit (cyber-warrior.org)
CVE-2018-7600CRITICALsob ataqueransomware18 jun 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Metasploit600
Cacti color filter authenticated SQLi to RCE
CVE-2020-1429517 jun 2020
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RISCO
abrir
GitHub PoC86
LPE for CVE-2020-1054 targeting Windows 7 x64
CVE-2020-1054HIGHsob ataque16 jun 2020
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
Metasploit300
AnyDesk GUI Format String Write
CVE-2020-1316016 jun 2020
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676316 jun 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
Exploit-DB
Gila CMS 1.11.8 - 'query' SQL Injection
CVE-2020-5515webappsphp16 jun 2020
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
28RISCO
abrir
VulnCheck XDB
local
CVE-2020-1054HIGHsob ataque16 jun 2020
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC721
Support ALL Windows Version
CVE-2020-0787HIGHsob ataqueransomware16 jun 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
VulnCheck XDB
local
CVE-2020-0787HIGHsob ataqueransomware16 jun 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
VulnCheck XDB
local
CVE-2020-0787HIGHsob ataqueransomware16 jun 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
GitHub PoC30
CVE-2020-5410 Spring Cloud Config directory traversal vulnerability
CVE-2020-5410HIGHsob ataque16 jun 2020
Directory Traversal with spring-cloud-config-server
100RISCO
abrir
GitHub PoC
Description and public exploit for CVE-2020-12712
CVE-2020-1271215 jun 2020
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RISCO
abrir
Metasploit300
Netgear R6700v3 Unauthenticated LAN Admin Password Reset
CVE-2020-10923MEDIUM15 jun 2020
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700
50RISCO
abrir
GitHub PoC1
A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing
CVE-2020-8816CRITICALsob ataque15 jun 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISCO
abrir
Metasploit300
Netgear R6700v3 Unauthenticated LAN Admin Password Reset
CVE-2020-10924HIGH15 jun 2020
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700
58RISCO
abrir
GitHub PoC
Description and public exploit for CVE-2020-12712
CVE-2020-1271215 jun 2020
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RISCO
abrir
Exploit-DB
SOS JobScheduler 1.13.3 - Stored Password Decryption
CVE-2020-12712remotemultiple15 jun 2020
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RISCO
abrir
GitHub PoC
sionnx/cve-2003-0282
CVE-2003-028214 jun 2020
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters bet
28RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-6418HIGHsob ataque13 jun 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC3
for 供養
CVE-2020-6418HIGHsob ataque13 jun 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC23
cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output
CVE-2020-0688HIGHsob ataqueransomware12 jun 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
Exploit-DB
Sysax MultiServer 6.90 - Reflected Cross Site Scripting
CVE-2020-13228webappsmultiple12 jun 2020
An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
23RISCO
abrir
GitHub PoC
freshdemo/ApacheStruts-CVE-2018-11776
CVE-2018-11776HIGHsob ataque12 jun 2020
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHsob ataque12 jun 2020
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
Exploit-DB
Avaya IP Office 11 - Password Disclosure
CVE-2020-7030MEDIUMwebappsmultiple12 jun 2020
IPO Information Disclosure
33RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHsob ataqueransomware12 jun 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
VulnCheck XDB
local
CVE-2017-9805HIGHsob ataque11 jun 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
Struts 2.5 - 2.5.12 REST Plugin XStream RCE
CVE-2017-9805HIGHsob ataque11 jun 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
Metasploit600
Inductive Automation Ignition Remote Code Execution
CVE-2020-1200411 jun 2020
The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior
23RISCO
abrir
anteriorpágina 766 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.